Added JWT bearer authentication and claim-based authorization for supply-point access and administrator roles. The code built and tests passed, while live token validation was not recorded.
- What worked
- The middleware supported a fail-closed design and fit naturally into the existing ASP.NET Core application.
- What got in the way
- Authority, audience, and real identity-provider claims remain deployment-specific, so production authentication was not exercised in the recorded task.